Podcasts about entra id

  • 61PODCASTS
  • 122EPISODES
  • 54mAVG DURATION
  • 5WEEKLY NEW EPISODES
  • Nov 14, 2025LATEST

POPULARITY

20172018201920202021202220232024


Best podcasts about entra id

Latest podcast episodes about entra id

Let's Talk Azure!
S6E28 - Automate Your Security Baseline with Microsoft's Open-Source Assessment Tool

Let's Talk Azure!

Play Episode Listen Later Nov 14, 2025 31:55 Transcription Available


In this episode, we dive into Microsoft's Zero Trust Assessment - an open-source, automated tool that scans hundreds of Entra ID and Intune settings against NIST, CISA, CIS, and Microsoft's own internal baselines. Discover how it aligns with the Secure Future Initiative, delivers actionable remediation, and turns Zero Trust from theory into measurable reality. Perfect for CISOs, SecOps teams, and anyone tired of spreadsheet audits. Key Takeaways: The Pain of Manual Zero Trust Audits What the Zero Trust Assessment Actually Does Why automate your security assessments What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.Read transcript

The PowerShell Podcast
200 Episodes of Community with Frank Lesniak

The PowerShell Podcast

Play Episode Listen Later Nov 10, 2025 70:46


In this milestone 200th episode of The PowerShell Podcast, Frank Lesniak returns to chat with Andrew Pla about automation, community, and what it means to “bet on yourself.” Frank shares his experiences leading cybersecurity and enterprise architecture projects, using PowerShell for AWS security automation, and developing tools to simplify complex data exports. He also discusses the upcoming PowerShell Summit, his work with DuPage Animal Friends, and the value of giving back through mentorship, community involvement, and open source.   Key Takeaways: PowerShell in the cloud – Frank dives deep into AWS automation and explains how PowerShell can simplify security and configuration management at scale. From console to community – After years of speaking and mentoring, Frank emphasizes how collaboration and consistent effort lead to career growth and confidence. Giving back through leadership – As VP of DuPage Animal Friends, Frank highlights the power of using your professional skills for good beyond tech. Guest Bio: Frank Lesniak is a Sr. Cybersecurity & Enterprise Technology Architect at West Monroe, where he leads a 45-member team focused on Microsoft's M365/Modern Work platform. His team specializes in navigating the technical complexities of corporate M&A, executing at-scale divestitures and integrations centered on Azure, Microsoft 365, Entra ID, Active Directory, and Windows. An active contributor to the tech community, Frank is a published author, open-source contributor, and a frequent speaker at conferences and user groups on topics including PowerShell, artificial intelligence, and offbeat technical talks related to his hobbies. In his local community, he serves as the Vice President of DuPage Animal Friends, a non-profit dedicated to supporting DuPage County's sole open-admission animal shelter.   Resource Links: Connect with Frank -https://linktr.ee/franklesniak Frank Lesniak on X (Twitter) – https://x.com/FrankLesniak Frank on LinkedIn – https://linkedin.com/in/flesniak Connect with Andrew - https://andrewpla.tech/links DuPage Animal Friends – https://dupageanimalfriends.org Previous Podcasts with Frank - https://powershellpodcast.podbean.com/?s=Frank%20Lesniak PowerShell Wednesdays – YouTube Playlist PDQ Discord (PowerShell Scripting Channel) – https://discord.gg/PDQ PowerShell Summit OnRamp Scholarship – https://www.powershellsummit.org/on-ramp/ The PowerShell Podcast on YouTube: https://youtu.be/cQvs5s3T1DA

Unofficial SAP on Azure podcast
#263 - ToW SuccessFactors integration & Role provisioning (Martin Raepple) | SAP on Azure Video Podcast

Unofficial SAP on Azure podcast

Play Episode Listen Later Oct 17, 2025 51:41


In episode 263 of our SAP on Azure video podcast we talk about Entra ID and SAP Cloud Identity Services. In the past we already had a few sessions with Martin Raepple where we talked about the integration of Entra ID with the SAP Cloud Identity Service. Today we will look at the SuccessFactors integraiton and role provisioning and we are happy to have Martin back with us.  Product management at its best!Find all the links mentioned here: https://www.saponazurepodcast.de/episode263Reach out to us for any feedback / questions:* Goran Condric: https://www.linkedin.com/in/gorancondric/* Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/ #Microsoft #SAP #Azure #SAPonAzure #Identity #EntraID #BTP

Unofficial SAP on Azure podcast
#262 - ToW Security with SAP and Microsoft (Martin Pankraz) | SAP on Azure Video Podcast

Unofficial SAP on Azure podcast

Play Episode Listen Later Oct 10, 2025 33:09


In episode 262 of our SAP on Azure video podcast we talk about Security. In the past, security was never really a prominent topic for SAP customers. When asked about their top 5 priorities in the next year, other topics were always on the top. To my suprise, this changed quite a bit: not only in the latest DSAG Survey Security came out as one of the most important topics. So with todays session, we want to kick off several sessions focused completely on Security with SAP and Microsoft. This goes way beyond using Entra ID for Signle Sign-On and my colleague Martin Pankraz has focused on this for years. So I am really glad to have Martin back with us to kick off the security related sessions. Find all the links mentioned here: https://www.saponazurepodcast.de/episode262Reach out to us for any feedback / questions:* Goran Condric: https://www.linkedin.com/in/gorancondric/* Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/ #Microsoft #SAP #Azure #SAPonAzure #Security #Sentinel #RISEwithSAP #MSDefender

Microsoft Mechanics Podcast
How to move Active Directory Source of Authority to Microsoft Entra ID and why

Microsoft Mechanics Podcast

Play Episode Listen Later Oct 8, 2025 9:41 Transcription Available


Strengthen your security posture by moving groups and users from Active Directory to Microsoft Entra. This gives you seamless access for your teams, stronger authentication with MFA and passwordless options, and centralized visibility into risks across your environment. Simplify hybrid identity management by reducing dual overhead, prioritizing key groups, migrating users without disruption, and automating policies with Graph or PowerShell. Jeremy Chapman, Microsoft 365 Director, shows how to start minimizing your local directory and make Microsoft Entra your source of authority to protect access everywhere. ► QUICK LINKS: 00:00 - Minimize Active Directory with Microsoft Entra 00:34 - Build a Strong Identity Foundation 01:28 - Reduce Dual Management Overhead 02:06 - Begin with Groups 03:04 - Automate with Graph & Policy Controls 03:50 - Access packages 06:00 - Move user objects to be cloud-managed 07:03 - Automate using scripts or code 09:17 - Wrap up ► Link References Get started at https://aka.ms/CloudManagedIdentity Use SOA scenarios at https://aka.ms/usersoadocs Group SOA scenarios at https://aka.ms/groupsoadocs Guidance for IT Architects on benefits of SOA at https://aka.ms/SOAITArchitectsGuidance ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics

ALEF SecurityCast
Ep#301 - Británie znovu žádá backdoor do šifrování a Evropská letiště v chaosu | SHRNUTÍ MĚSÍCE

ALEF SecurityCast

Play Episode Listen Later Oct 7, 2025 48:12


V této epizodě SecurityCastu se podíváme na ransomware útok, který ochromil evropská letiště a odhalil slabiny v systémech pro odbavení cestujících, na dvojici aktivně zneužívaných zero-day zranitelností v Cisco ASA, které ohrožují i federální agentury v USA, a na nový tlak britské vlády, která znovu žádá zadní vrátka do šifrování Applu. Společně s Janem Kopřivou rozebereme také zranitelnost CarPlay, která umožňuje hacknout infotainment systém auta na dálku, a podíváme se na nové objevy z výzkumu ESETu i Microsoft Entra ID. Epizoda přináší přehled klíčových událostí měsíce v kyberbezpečnosti – od letectví a automobilů až po globální otázky ochrany dat.One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens: https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/

BlåSkjerm Brødrene
#25-15 MVP Dagen - Marius Solbakken Mellum

BlåSkjerm Brødrene

Play Episode Listen Later Sep 29, 2025 13:06


Broder Olav fortsetter MVP Dagen spesial, og ikke bare finner han frem en gammel kjenning, men han trekker opp en broder fra skattekisten. Marius består tilgangskontrollen med glans, kanskje er det på tide å flytte den fra AD til Entra ID? Hosted on Acast. See acast.com/privacy for more information.

Black Hills Information Security
Dirk-Jan Mollema walks us through The Entra ID Cross-Tenant Vulnerability Discovery– 2025-09-22

Black Hills Information Security

Play Episode Listen Later Sep 25, 2025 60:18


???? Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.com 00:00 - PreShow Banter™ — Unnatural European Fridges03:34 - The Entra ID Cross-Tenant Vulnerability Discovery – BHIS - Talkin' Bout [infosec] News 2025-09-2204:14 - Story # 1: One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens21:32 - Story # 2: Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages40:50 - OSSPREY – NPM Package @Ctrl/Tinycolor Compromised: Shai Hulud Malware Targets Secrets and Persistence51:41 - Story # 3: Verified Steam game steals streamer's cancer treatment donations57:16 - Story # 4: Heathrow warns of second day of disruption after cyber-attack

Security Now (MP3)
SN 1044: The EU's Online Age Verification - Consumer Reports vs. Microsoft

Security Now (MP3)

Play Episode Listen Later Sep 24, 2025 181:56


Consumer Reports on Windows 10 updates. Waste (not fraud or abuse) within DoD Cyberoperations. China's DeepSeek produces deliberately flawed code. WebAssembly v3.0 officially released. Firefox v143 updates and new features. Firefox for Android now offers DoH. A nearly terminal flaw in Microsoft's Entra ID. Chrome hits its 6th 0-day this year. Emergency update. DRAM (now DDR5) still vulnerable to RowHammer. SAMSUNG kitchen refrigerators begin showing ads. China says no to NVIDIA. 300 more (new) NPM maliciouspackages found and removed. The EU is already testing proper online age verification. Show Notes - https://www.grc.com/sn/SN-1044-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: bigid.com/securitynow go.acronis.com/twit zscaler.com/security 1password.com/securitynow hoxhunt.com/securitynow

Risky Business
Risky Business #808 -- Insane megabug in Entra left all tenants exposed

Risky Business

Play Episode Listen Later Sep 24, 2025 52:37


On this week's show Patrick Gray and special guest Rob Joyce discuss the week's cybersecurity news, including: Secret Service raids a SIM farm in New York MI6 launches a dark web portal Are the 2023 Scattered Spider kids finally getting their comeuppance? Production halt continues for Jaguar Land Rover GitHub tightens its security after Shai-Hulud worm This week's episode is sponsored by Sublime Security. In this week's sponsor interview, Sublime founder and CEO Josh Kamdjou joins host Patrick Gray to chat about the pros and cons of using agentic AI in an email security platform. This episode is also available on YouTube Show notes U.S. Secret Service disrupts telecom network that threatened NYC during U.N. General Assembly MI6 launches darkweb portal to recruit foreign spies | The Record from Recorded Future News One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens | dirkjanm.io Github npm changes Flights across Europe delayed after cyberattack targets third-party vendor | Cybersecurity Dive Major European airports work to restore services after cyberattack on check-in systems | The Record from Recorded Future News When “Goodbye” isn't the end: Scattered LAPSUS$ Hunters hack on | DataBreaches.Net UK arrests 2 more alleged Scattered Spider hackers over London transit system breach | Cybersecurity Dive Alleged Scattered Spider member turns self in to Las Vegas police | The Record from Recorded Future News Las Vegas police arrest minor accused of high-profile 2023 casino attacks | CyberScoop DOJ: Scattered Spider took $115 million in ransoms, breached a US court system | The Record from Recorded Future News vx-underground on X: "Scattered Spider ransoms company for 964BTC - wtf_thats_alot.jpeg - Document says "Cost of BTC at time was $36M" - $36M / 964BTC = $37.5K - BTC value was $37.5K in November, 2023 - Google "Ransomware, November, 2023" - omfg.exe https://t.co/uv2EzbL5HT" | X JLR ‘cyber shockwave ripping through UK industry' as supplier share price plummets by 55% | The Record from Recorded Future News Jaguar Land Rover to extend production pause into October following cyberattack | Cybersecurity Dive New plan would give Congress another 18 months to revisit Section 702 surveillance powers | The Record from Recorded Future News AI-powered vulnerability detection will make things worse, not better, former US cyber official warns | Cybersecurity Dive

All TWiT.tv Shows (MP3)
Security Now 1044: The EU's Online Age Verification

All TWiT.tv Shows (MP3)

Play Episode Listen Later Sep 24, 2025 181:41 Transcription Available


Consumer Reports on Windows 10 updates. Waste (not fraud or abuse) within DoD Cyberoperations. China's DeepSeek produces deliberately flawed code. WebAssembly v3.0 officially released. Firefox v143 updates and new features. Firefox for Android now offers DoH. A nearly terminal flaw in Microsoft's Entra ID. Chrome hits its 6th 0-day this year. Emergency update. DRAM (now DDR5) still vulnerable to RowHammer. SAMSUNG kitchen refrigerators begin showing ads. China says no to NVIDIA. 300 more (new) NPM maliciouspackages found and removed. The EU is already testing proper online age verification. Show Notes - https://www.grc.com/sn/SN-1044-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: bigid.com/securitynow go.acronis.com/twit zscaler.com/security 1password.com/securitynow hoxhunt.com/securitynow

Security Now (Video HD)
SN 1044: The EU's Online Age Verification - Consumer Reports vs. Microsoft

Security Now (Video HD)

Play Episode Listen Later Sep 24, 2025


Consumer Reports on Windows 10 updates. Waste (not fraud or abuse) within DoD Cyberoperations. China's DeepSeek produces deliberately flawed code. WebAssembly v3.0 officially released. Firefox v143 updates and new features. Firefox for Android now offers DoH. A nearly terminal flaw in Microsoft's Entra ID. Chrome hits its 6th 0-day this year. Emergency update. DRAM (now DDR5) still vulnerable to RowHammer. SAMSUNG kitchen refrigerators begin showing ads. China says no to NVIDIA. 300 more (new) NPM maliciouspackages found and removed. The EU is already testing proper online age verification. Show Notes - https://www.grc.com/sn/SN-1044-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: bigid.com/securitynow go.acronis.com/twit zscaler.com/security 1password.com/securitynow hoxhunt.com/securitynow

Security Now (Video HI)
SN 1044: The EU's Online Age Verification - Consumer Reports vs. Microsoft

Security Now (Video HI)

Play Episode Listen Later Sep 24, 2025


Consumer Reports on Windows 10 updates. Waste (not fraud or abuse) within DoD Cyberoperations. China's DeepSeek produces deliberately flawed code. WebAssembly v3.0 officially released. Firefox v143 updates and new features. Firefox for Android now offers DoH. A nearly terminal flaw in Microsoft's Entra ID. Chrome hits its 6th 0-day this year. Emergency update. DRAM (now DDR5) still vulnerable to RowHammer. SAMSUNG kitchen refrigerators begin showing ads. China says no to NVIDIA. 300 more (new) NPM maliciouspackages found and removed. The EU is already testing proper online age verification. Show Notes - https://www.grc.com/sn/SN-1044-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: bigid.com/securitynow go.acronis.com/twit zscaler.com/security 1password.com/securitynow hoxhunt.com/securitynow

Radio Leo (Audio)
Security Now 1044: The EU's Online Age Verification

Radio Leo (Audio)

Play Episode Listen Later Sep 24, 2025 181:56 Transcription Available


Consumer Reports on Windows 10 updates. Waste (not fraud or abuse) within DoD Cyberoperations. China's DeepSeek produces deliberately flawed code. WebAssembly v3.0 officially released. Firefox v143 updates and new features. Firefox for Android now offers DoH. A nearly terminal flaw in Microsoft's Entra ID. Chrome hits its 6th 0-day this year. Emergency update. DRAM (now DDR5) still vulnerable to RowHammer. SAMSUNG kitchen refrigerators begin showing ads. China says no to NVIDIA. 300 more (new) NPM maliciouspackages found and removed. The EU is already testing proper online age verification. Show Notes - https://www.grc.com/sn/SN-1044-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: bigid.com/securitynow go.acronis.com/twit zscaler.com/security 1password.com/securitynow hoxhunt.com/securitynow

Security Now (Video LO)
SN 1044: The EU's Online Age Verification - Consumer Reports vs. Microsoft

Security Now (Video LO)

Play Episode Listen Later Sep 24, 2025


Consumer Reports on Windows 10 updates. Waste (not fraud or abuse) within DoD Cyberoperations. China's DeepSeek produces deliberately flawed code. WebAssembly v3.0 officially released. Firefox v143 updates and new features. Firefox for Android now offers DoH. A nearly terminal flaw in Microsoft's Entra ID. Chrome hits its 6th 0-day this year. Emergency update. DRAM (now DDR5) still vulnerable to RowHammer. SAMSUNG kitchen refrigerators begin showing ads. China says no to NVIDIA. 300 more (new) NPM maliciouspackages found and removed. The EU is already testing proper online age verification. Show Notes - https://www.grc.com/sn/SN-1044-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: bigid.com/securitynow go.acronis.com/twit zscaler.com/security 1password.com/securitynow hoxhunt.com/securitynow

All TWiT.tv Shows (Video LO)
Security Now 1044: The EU's Online Age Verification

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Sep 24, 2025 181:26 Transcription Available


Consumer Reports on Windows 10 updates. Waste (not fraud or abuse) within DoD Cyberoperations. China's DeepSeek produces deliberately flawed code. WebAssembly v3.0 officially released. Firefox v143 updates and new features. Firefox for Android now offers DoH. A nearly terminal flaw in Microsoft's Entra ID. Chrome hits its 6th 0-day this year. Emergency update. DRAM (now DDR5) still vulnerable to RowHammer. SAMSUNG kitchen refrigerators begin showing ads. China says no to NVIDIA. 300 more (new) NPM maliciouspackages found and removed. The EU is already testing proper online age verification. Show Notes - https://www.grc.com/sn/SN-1044-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: bigid.com/securitynow go.acronis.com/twit zscaler.com/security 1password.com/securitynow hoxhunt.com/securitynow

Radio Leo (Video HD)
Security Now 1044: The EU's Online Age Verification

Radio Leo (Video HD)

Play Episode Listen Later Sep 24, 2025 181:26 Transcription Available


Consumer Reports on Windows 10 updates. Waste (not fraud or abuse) within DoD Cyberoperations. China's DeepSeek produces deliberately flawed code. WebAssembly v3.0 officially released. Firefox v143 updates and new features. Firefox for Android now offers DoH. A nearly terminal flaw in Microsoft's Entra ID. Chrome hits its 6th 0-day this year. Emergency update. DRAM (now DDR5) still vulnerable to RowHammer. SAMSUNG kitchen refrigerators begin showing ads. China says no to NVIDIA. 300 more (new) NPM maliciouspackages found and removed. The EU is already testing proper online age verification. Show Notes - https://www.grc.com/sn/SN-1044-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: bigid.com/securitynow go.acronis.com/twit zscaler.com/security 1password.com/securitynow hoxhunt.com/securitynow

Paul's Security Weekly
Design Errors in Entra ID, Design Defenses in iOS, Design Difficulties in DeepSeek - ASW #349

Paul's Security Weekly

Play Episode Listen Later Sep 23, 2025 58:43


In the news, Microsoft encounters a new cascade of avoidable errors with Entra ID, Apple improves iOS with hardware-backed memory safety, DeepSeek demonstrates the difficulty in reviewing models, curl reduces risk by eliminating code, preserving the context of code reviews, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-349

Paul's Security Weekly TV
Design Errors in Entra ID, Design Defenses in iOS, Design Difficulties in DeepSeek - ASW #349

Paul's Security Weekly TV

Play Episode Listen Later Sep 23, 2025 58:43


In the news, Microsoft encounters a new cascade of avoidable errors with Entra ID, Apple improves iOS with hardware-backed memory safety, DeepSeek demonstrates the difficulty in reviewing models, curl reduces risk by eliminating code, preserving the context of code reviews, and more! Show Notes: https://securityweekly.com/asw-349

Application Security Weekly (Audio)
Design Errors in Entra ID, Design Defenses in iOS, Design Difficulties in DeepSeek - ASW #349

Application Security Weekly (Audio)

Play Episode Listen Later Sep 23, 2025 58:43


In the news, Microsoft encounters a new cascade of avoidable errors with Entra ID, Apple improves iOS with hardware-backed memory safety, DeepSeek demonstrates the difficulty in reviewing models, curl reduces risk by eliminating code, preserving the context of code reviews, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-349

Application Security Weekly (Video)
Design Errors in Entra ID, Design Defenses in iOS, Design Difficulties in DeepSeek - ASW #349

Application Security Weekly (Video)

Play Episode Listen Later Sep 23, 2025 58:43


In the news, Microsoft encounters a new cascade of avoidable errors with Entra ID, Apple improves iOS with hardware-backed memory safety, DeepSeek demonstrates the difficulty in reviewing models, curl reduces risk by eliminating code, preserving the context of code reviews, and more! Show Notes: https://securityweekly.com/asw-349

The CyberWire
Grounded by ransomware.

The CyberWire

Play Episode Listen Later Sep 22, 2025 28:57


A major ransomware attack disrupts airport operations across Europe. Congress is on the verge of letting major cyber legislation expire. A critical flaw nearly allowed total compromise of every Entra ID tenant. Automaker Stellantis confirms a data breach. Fortra patches a critical flaw in its GoAnywhere MFT software. Europol leads a major operation against online child sexual exploitation. Three of the cybersecurity industry's biggest players opt out of MITRE's 2025 ATT&CK Evaluations. A compromised Steam game drains a cancer patient's donations. Business Breakdown. Andrzej Olchawa and Milenko Starcik from VisionSpace join Maria Varmazis, host of T-Minus Space on hacking satellites. How one kid got tangled in Scattered Spider's web. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Andrzej Olchawa and Milenko Starcik from VisionSpace are speaking with Maria Varmazis, host of T-Minus Space on hacking satellites. Selected Reading EU cyber agency says airport software held to ransom by criminals (BBC News) Cyber threat information law hurtles toward expiration, with poor prospects for renewal (CyberScoop) Microsoft Entra ID flaw allowed hijacking any company's tenant (Bleeping Computer) Stellantis says a third-party vendor spilled customer data (The Register) Fortra Patches Critical GoAnywhere MFT Vulnerability (SecurityWeek) AI Forensics Help Europol Track 51 Children in Global Online Abuse Case (HackRead) Cyber Threat Detection Vendors Pull Out of MITRE Evaluations Test (Infosecurity Magazine) Verified Steam game steals streamer's cancer treatment donations (Bleeping Computer) CrowdStrike and Check Point intend to acquire AI security firms. (N2K CyberWire Business Briefing)  ‘I Was a Weird Kid': Jailhouse Confessions of a Teen Hacker (Bloomberg) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Cyber Security Today
Extinction Level Cyber Vulnerability Now Fixed

Cyber Security Today

Play Episode Listen Later Sep 22, 2025 15:22 Transcription Available


Cybersecurity Today: Major Vulnerabilities and Attacks Uncovered Join host David Shipley for today's cybersecurity updates on the last day of summer 2025. In this episode, we delve deep into Microsoft's critical Entra ID vulnerability, a cyber attack crippling major European airports, the rise of SpamGPT targeting phishing operations, and the alarming zero-click flaw in OpenAI's deep research agent. Hear about Canadian Police's big win against the shadowy Trade Ogre crypto platform and their $40 million asset seizure. Buckle up for a reality check on the evolving cyber threats and their impact on global security. 00:00 Introduction and Overview 00:55 Microsoft's Extinction Level Vulnerability 05:19 European Airports Cyber Attack 08:20 SpamGPT: AI for Cyber Criminals 09:53 Shadow Leak: Zero Click AI Vulnerability 12:09 Trade Ogre Takedown 14:50 Conclusion and Upcoming Events

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast
SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches

SANS Internet Stormcenter Daily Network/Cyber Security and Information Security Stormcast

Play Episode Listen Later Sep 18, 2025 6:31


CTRL-Z DLL Hooking Attackers may use a simple reload trick to overwrite breakpoints left by analysts to reverse malicious binaries. https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294 Global Admin in every Entra ID tenant via Actor tokens As part of September s patch Tuesday, Microsoft patched CVE-2025-55241. The discoverer of the vulnerability, Dirk-jan Mollema has published a blog post showing how this vulnerability could have been exploited. https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/ WatchGuard Firebox iked Out of Bounds Write Vulnerability CVE-2025-9242 WatchGuard patched an out-of-bounds write vulnerability, which could allow an unauthenticated attacker to compromise the devices. https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015 NVidia Triton Inference Server NVIDIA patched critical vulnerabilities in its Triton Inference Server. https://nvidia.custhelp.com/app/answers/detail/a_id/5691

Unofficial SAP on Azure podcast
#254 - TOW Entra ID Governance from Customer perspective (Roj Koc) | SAP on Azure Video Podcast

Unofficial SAP on Azure podcast

Play Episode Listen Later Aug 15, 2025 56:21


In episode 254 of our SAP on Azure video podcast we talk about Entra ID Governance from a Customer perspectiveWe continue today with the topics around Entra ID and SAP. We have covered different aspects of the integration of Entra ID and SAP in different ways in the past, but we thought that today we could take a look from a customer perspective. I am glad to have Roj Koc with us today, who is working closely with customers in Denmark and northern Europe to share what he is seeing in the market. Find all the links mentioned here: https://www.saponazurepodcast.de/episode254Reach out to us for any feedback / questions:* Robert Boban: https://www.linkedin.com/in/rboban/* Goran Condric: https://www.linkedin.com/in/gorancondric/* Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/ #Microsoft #SAP #Azure #SAPonAzure #EntraID #IAG #SAPIDM

Risky Business
Risky Business #802 -- Accessing internal Microsoft apps with your Hotmail creds

Risky Business

Play Episode Listen Later Aug 13, 2025 60:00


On this week's show Patrick Gray and Adam Boileau discuss the week's cybersecurity news, including: CISA warns about the path from on-prem Exchange to the cloud Microsoft awards a crisp zero dollar bill for a report about what a mess its internal Entra-authed apps are Everyone and their dog seems to have a shell in US Federal Court information systems Google pays $250k for a Chrome sandbox escape Attackers use javascript in adult SVG files to … farm facebook likes?! SonicWall says users aren't getting hacked with an 0day… this time. This week's episode is sponsored by SpecterOps. Chief product officer Justin Kohler talks about how the flagship Bloodhound tool has evolved to map attack paths anywhere. Bring your own applications, directories and systems into the graph, and join the identity attacks together. This episode is also available on Youtube. Show notes CISA, Microsoft issue alerts on ‘high-severity' Exchange vulnerability | The Record from Recorded Future News Advanced Active Directory to Entra ID lateral movement techniques Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications Cartels may be able to target witnesses after major court hack Federal judiciary tightens digital security as it deals with ‘escalated cyberattacks' | The Record from Recorded Future News Citrix NetScaler flaws lead to critical infrastructure breaches | Cybersecurity Dive DARPA touts value of AI-powered vulnerability detection as it announces competition winners | Cybersecurity Dive Buttercup is now open-source! HTTP/1.1 must die: the desync endgame US confirms takedown of BlackSuit ransomware gang that racked up $370 million in ransoms | The Record from Recorded Future News North Korean cyber-espionage group ScarCruft adds ransomware in recent attack | The Record from Recorded Future News Adult sites are stashing exploit code inside racy .svg files - Ars Technica Google pays 250k for Chromium sandbox escape SonicWall says recent attack wave involved previously disclosed flaw, not zero-day | Cybersecurity Dive Two groups exploit WinRAR flaws in separate cyber-espionage campaigns | The Record from Recorded Future News Tornado Cash cofounder dodges money laundering conviction, found guilty of lesser charge | The Record from Recorded Future News Hackers Hijacked Google's Gemini AI With a Poisoned Calendar Invite to Take Over a Smart Home | WIRED Malware in Open VSX: These Vibes Are Off How attackers are using Active Directory Federation Services to phish with legit office.com links Introducing our guide to phishing detection evasion techniques The State of Attack Path Management

RunAs Radio
The Power of the Graph with Tony Redmond

RunAs Radio

Play Episode Listen Later Aug 13, 2025 40:47


Are you tapping the power of Microsoft Graph? Richard chats with Tony Redmond about his work teaching people to leverage Microsoft Graph and all the insights it can provide about their organization. Tony views Graph as one of the key skills a sysadmin needs to manage an M365 tenant, alongside Exchange Online, SharePoint, and Teams. Throw in some Entra ID skills with Graph and you're ready to take on the rest - and there's a lot! Tony is also responsible for the excellent Office 365 for IT Pros book, now in its 12th edition for 2026. These are the fundamentals that can help you embrace the Copilot future we're all facing - and there's a lot to learn!LinksGraph PowerShell SDKAzure AutomationOffice 365 for IT Pros 2026 EditionMaesterAgent Governance in M365Secure Future InitiativeLinkable Identifiers in Microsoft EntraRecorded July 24, 2025

Community IT Innovators Nonprofit Technology Topics
Microsoft Unified Security Administration Deadline Approaching with Steve Longenecker

Community IT Innovators Nonprofit Technology Topics

Play Episode Listen Later Aug 8, 2025 21:03


On September 30th Microsoft will only support a new unified multi-factor authentication control configuration. What does this mean for your nonprofit?In March 2023 Microsoft announced that after September 30th, 2025, they would no longer automatically support “legacy” multi-factor authentication controls in the Microsoft 365 Entra ID and General Admin administration portals. The methods your staff are using now will not automatically roll over to be allowed via the new admin dashboard after that date. Steve Longenecker, Community IT's Director of IT Consulting, explains to Carolyn the implications for nonprofits of this change and the Microsoft unified security administration deadline.The takeaways: The new unified authentication dashboard is available now to Microsoft 365 admins.The new Authentication Methods page does not inherit methods allowed in the legacy controls. An administrator needs to manually enable the MFA methods your organization wants to allow. Old MFA options your staff are using now will not roll over automatically to the new dashboard.Microsoft and Community IT are pushing admins to use this opportunity to to exclude less secure MFA methods. Community IT advises against allowing SMS texting and one-time codes sent to personal email addresses as MFA methods. You can upgrade and implement the new MFA and password reset options at any time, and we advise you to do this before September 30, whether or not Microsoft grants an extension of the deadline.If you just started using Microsoft 365 for Nonprofits, you don't need to worry about the deadline because your initial configuration would already be using the new Authentication Methods page. If you haven't made the change or don't know, you need to check before September 30, 2025.This change is visible only to Microsoft administrators, who should be making the change and informing staff where appropriate. If you are a nonprofit leader or board member and have not heard from your IT Director or outsourced IT, check with them to understand the plan for your organization. If you are a nonprofit staffer, pay attention to directions on using the safest MFA to protect your nonprofit.While not directly impacted by this deadline from Microsoft, Carolyn and Steve discuss the importance of “phish-resistant” MFA, preventing Attacker-in-the-Middle (AitM) attacks, for executives and staff working in finance, IT and other highly targeted areas of your operations. NOTE: The timelines on Microsoft changes do sometimes shift, and we are working to keep you updated. Please check for the most recent blog or podcast from us to ensure you have the most recent update. _______________________________Start a conversation :) Register to attend a webinar in real time, and find all past transcripts at https://communityit.com/webinars/ email Carolyn at cwoodard@communityit.com on LinkedIn Thanks for listening.

Unofficial SAP on Azure podcast
#253 - TOW Integrating SAP HCM with Microsoft Entra ID Governance (Chetan Desai) | SAP on Azure Video Podcast

Unofficial SAP on Azure podcast

Play Episode Listen Later Aug 8, 2025 45:10


In episode 253 of our SAP on Azure video podcast we talk about SAP HCM with Microsoft Entra ID Governance. In previous episodes we have talked about the extensibility concept of Entra ID, Entra ID Governance and other SAP integration. In a lot of customer scenarios, these integrations are relevant in the context of HCM. So today -- after more than 3 years -- I am happy to welcome Chetan Desai with us again. He recently published new guidance on integrating SAP HCM with Microsoft Entra ID Governance, using flexible provisioning options like CSV, SAP BAPI, or SAP IDocsFind all the links mentioned here: https://www.saponazurepodcast.de/episode253Reach out to us for any feedback / questions:* Goran Condric: https://www.linkedin.com/in/gorancondric/* Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/ #Microsoft #SAP #Azure #SAPonAzure #HCM #EntraID

ITSPmagazine | Technology. Cybersecurity. Society
Making Honeypots Useful Again: Identity Security, Deception, and the Art of Detection | A Conversation with Sean Metcalf | Redefining CyberSecurity with Sean Martin

ITSPmagazine | Technology. Cybersecurity. Society

Play Episode Listen Later Jul 30, 2025 31:48


⬥GUEST⬥Sean Metcalf, Identity Security Architect at TrustedSec | On LinkedIn: https://www.linkedin.com/in/seanmmetcalf/⬥HOST⬥Host: Sean Martin, Co-Founder at ITSPmagazine and Host of Redefining CyberSecurity Podcast | On LinkedIn: https://www.linkedin.com/in/imsmartin/ | Website: https://www.seanmartin.com⬥EPISODE NOTES⬥Sean Metcalf, a frequent speaker at conferences like Black Hat, DEF CON, and RSAC, brings a sharp focus to identity security—especially within Microsoft environments like Active Directory and Entra ID. In this episode, he walks through the practical and tactical role of honeypots and deception in detecting intrusions early and with higher fidelity.While traditional detection tools often aim for broad coverage, honeypots flip the script by offering precise signal amidst the noise. Metcalf discusses how defenders can take advantage of the attacker's need to enumerate systems and accounts after gaining access. That need becomes an opportunity to embed traps—accounts or assets that should never be touched unless someone is doing something suspicious.One core recommendation: repurpose old service accounts with long-lived passwords and believable naming conventions. These make excellent bait for Kerberoasting attempts, especially when paired with service principal names (SPNs) that mimic actual applications. Metcalf outlines how even subtle design choices—like naming conventions that fit organizational patterns—can make a honeypot more convincing and effective.He also draws a distinction between honeypots and deception technologies. While honeypots often consist of a few well-placed traps, deception platforms offer full-scale phantom environments. Regardless of approach, the goal remains the same: attackers shouldn't be able to move around your environment without tripping over something that alerts the defender.Importantly, Metcalf emphasizes that alerts triggered by honeypots are high-value. Since no legitimate user should interact with them, they provide early warning with low false positives. He also addresses the internal politics of deploying these traps, from coordinating with IT operations to ensuring SOC teams have the right procedures in place to respond effectively.Whether you're running a high-end deception platform or just deploying free tokens and traps, the message is clear: identity is the new perimeter, and a few strategic tripwires could mean the difference between breach detection and breach denial.⬥SPONSORS⬥LevelBlue: https://itspm.ag/attcybersecurity-3jdk3ThreatLocker: https://itspm.ag/threatlocker-r974⬥RESOURCES⬥Inspiring Post: https://www.linkedin.com/posts/activity-7353806074694541313-xzQl/Article: The Art of the Honeypot Account: Making the Unusual Look Normal: https://www.hub.trimarcsecurity.com/post/the-art-of-the-honeypot-account-making-the-unusual-look-normalArticle: Trimarc Research: Detecting Kerberoasting Activity: https://www.hub.trimarcsecurity.com/post/trimarc-research-detecting-kerberoasting-activityArticle: Detecting Password Spraying with Security Event Auditing: https://www.hub.trimarcsecurity.com/post/trimarc-research-detecting-password-spraying-with-security-event-auditing⬥ADDITIONAL INFORMATION⬥✨ More Redefining CyberSecurity Podcast: 

Redefining CyberSecurity
Making Honeypots Useful Again: Identity Security, Deception, and the Art of Detection | A Conversation with Sean Metcalf | Redefining CyberSecurity with Sean Martin

Redefining CyberSecurity

Play Episode Listen Later Jul 30, 2025 31:48


⬥GUEST⬥Sean Metcalf, Identity Security Architect at TrustedSec | On LinkedIn: https://www.linkedin.com/in/seanmmetcalf/⬥HOST⬥Host: Sean Martin, Co-Founder at ITSPmagazine and Host of Redefining CyberSecurity Podcast | On LinkedIn: https://www.linkedin.com/in/imsmartin/ | Website: https://www.seanmartin.com⬥EPISODE NOTES⬥Sean Metcalf, a frequent speaker at conferences like Black Hat, DEF CON, and RSAC, brings a sharp focus to identity security—especially within Microsoft environments like Active Directory and Entra ID. In this episode, he walks through the practical and tactical role of honeypots and deception in detecting intrusions early and with higher fidelity.While traditional detection tools often aim for broad coverage, honeypots flip the script by offering precise signal amidst the noise. Metcalf discusses how defenders can take advantage of the attacker's need to enumerate systems and accounts after gaining access. That need becomes an opportunity to embed traps—accounts or assets that should never be touched unless someone is doing something suspicious.One core recommendation: repurpose old service accounts with long-lived passwords and believable naming conventions. These make excellent bait for Kerberoasting attempts, especially when paired with service principal names (SPNs) that mimic actual applications. Metcalf outlines how even subtle design choices—like naming conventions that fit organizational patterns—can make a honeypot more convincing and effective.He also draws a distinction between honeypots and deception technologies. While honeypots often consist of a few well-placed traps, deception platforms offer full-scale phantom environments. Regardless of approach, the goal remains the same: attackers shouldn't be able to move around your environment without tripping over something that alerts the defender.Importantly, Metcalf emphasizes that alerts triggered by honeypots are high-value. Since no legitimate user should interact with them, they provide early warning with low false positives. He also addresses the internal politics of deploying these traps, from coordinating with IT operations to ensuring SOC teams have the right procedures in place to respond effectively.Whether you're running a high-end deception platform or just deploying free tokens and traps, the message is clear: identity is the new perimeter, and a few strategic tripwires could mean the difference between breach detection and breach denial.⬥SPONSORS⬥LevelBlue: https://itspm.ag/attcybersecurity-3jdk3ThreatLocker: https://itspm.ag/threatlocker-r974⬥RESOURCES⬥Inspiring Post: https://www.linkedin.com/posts/activity-7353806074694541313-xzQl/Article: The Art of the Honeypot Account: Making the Unusual Look Normal: https://www.hub.trimarcsecurity.com/post/the-art-of-the-honeypot-account-making-the-unusual-look-normalArticle: Trimarc Research: Detecting Kerberoasting Activity: https://www.hub.trimarcsecurity.com/post/trimarc-research-detecting-kerberoasting-activityArticle: Detecting Password Spraying with Security Event Auditing: https://www.hub.trimarcsecurity.com/post/trimarc-research-detecting-password-spraying-with-security-event-auditing⬥ADDITIONAL INFORMATION⬥✨ More Redefining CyberSecurity Podcast: 

Microsoft Mechanics Podcast
NEW Conditional Access Optimization Agent in Microsoft Entra + Security Copilot in Entra updates

Microsoft Mechanics Podcast

Play Episode Listen Later Jul 15, 2025 8:52 Transcription Available


Troubleshoot identity issues, investigate risky users and apps, and optimize Conditional Access policies using natural language—with built-in AI from Microsoft Security Copilot in Microsoft Entra. Instead of switching between logs, PowerShell, and spreadsheets, Security Copilot centralizes insights for faster, more focused action. Resolve compromised accounts, uncover ownerless or high-risk apps, and tighten policy coverage with clear insights, actionable recommendations, and auto-generated policies. Strengthen security posture and reclaim time with a smarter, more efficient approach powered by Security Copilot. Diana Vicezar, Microsoft Entra Product Manager, shares how to streamline investigations and policy management using AI-driven insights and automation.  ► QUICK LINKS:  00:00 - Microsoft Entra with Security Copilot 01:26 - Conditional Access Optimization Agent 03:35 - Investigate risky users 05:49 - Investigate risky apps 07:34 - Personalized security posture recommendations 08:20 - Wrap up ► Link References Check out https://aka.ms/SecurityCopilotAgentsinMicrosoftEntra ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics  

Unofficial SAP on Azure podcast
#246 - TOW Customize Access Governance Workflows (Martin Raepple) | SAP on Azure Video Podcast

Unofficial SAP on Azure podcast

Play Episode Listen Later Jun 19, 2025 58:36


In episode 246 of our SAP on Azure video podcast we talk about SAP Identity Management and Microsoft Entra ID. Since the announcement from SAP about SAP IDM, a lot of customers have already started their journey to move to Entra ID. We have had several customers talking about their experience and also hosted several hands-on sessions. Martin Raepple is key player in most of these discussions and today we want to show in more detail how the journey is evolving. To today he shows us how to integrate Microsoft Entra with SAP Cloud Identity Services and leverage Microsoft Entra's advanced features to migrate and modernize existing SAP IDM workflows, using self-service UIs, integration with SAP data sources, and much more.Find all the links mentioned here: https://www.saponazurepodcast.de/episode246Reach out to us for any feedback / questions:* Goran Condric: https://www.linkedin.com/in/gorancondric/* Holger Bruchelt: https://www.linkedin.com/in/holger-bruchelt/ #Microsoft #SAP #Azure #SAPonAzure #SSO #IDM #EntraID #SAPIAS #Governance

The CyberWire
Cloudflare's cloudy day resolved.

The CyberWire

Play Episode Listen Later Jun 13, 2025 29:03


Cloudflare says yesterday's widespread outage was not caused by a cyberattack. Predator mobile spyware remains highly active. Microsoft is investigating ongoing Microsoft 365 authentication services issues. An account takeover campaign targets Entra ID users by abusing a popular pen testing tool. Palo Alto Networks documents a JavaScript obfuscation method dubbed “JSFireTruck.” Trend Micro and Mitel patch multiple high-severity vulnerabilities. CISA issues multiple advisories. My Hacking Humans cohost Joe Carrigan joins us to discuss linkless recruiting scams. Uncle Sam wants an AI chatbot.  Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you'll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest Today, we are joined by Joe Carrigan, one of Dave's Hacking Humans co-hosts, to talk about linkless recruiting scams. You can learn more in this article from The Record: FIN6 cybercriminals pose as job seekers on LinkedIn to hack recruiters. Tune in to Hacking Humans each Thursday on your favorite podcast app to hear the latest on the social engineering scams that are making the headlines from Joe, Dave and their co-host Maria Varmazis.  Selected Reading Cloudflare: Outage not caused by security incident, data is safe (Bleeping Computer) Predator Mobile Spyware Remains Consistent with New Design Changes to Evade Detection (Cyber Security News) Microsoft confirms auth issues affecting Microsoft 365 users (Bleeping Computer) TeamFiltration Abused in Entra ID Account Takeover Campaign (SecurityWeek) 270K websites injected with ‘JSF-ck' obfuscated code (SC Media) Palo Alto Networks Patches Series of Vulnerabilities (Infosecurity Magazine) SimpleHelp Vulnerability Exploited Against Utility Billing Software Users (SecurityWeek) Trend Micro fixes critical vulnerabilities in multiple products (Bleeping Computer) Critical Vulnerability Exposes Many Mitel MiCollab Instances to Remote Hacking  (SecurityWeek) CISA Releases Ten Industrial Control Systems Advisories (CISA) Trump team leaks AI plans in public GitHub repository (The Register) Want to hear your company in the show? You too can reach the most influential leaders and operators in the industry. Here's our media kit. Contact us at cyberwire@n2k.com to request more info. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc. Learn more about your ad choices. Visit megaphone.fm/adchoices

Cyber Briefing
June 12, 2025 - Cyber Briefing

Cyber Briefing

Play Episode Listen Later Jun 12, 2025 13:13


If you like what you hear, please subscribe, leave us a review and tell a friend!

Microsoft Mechanics Podcast
Fix Identity Sprawl + Optimize Microsoft Entra

Microsoft Mechanics Podcast

Play Episode Listen Later Jun 10, 2025 11:04 Transcription Available


Strengthen your security posture in Microsoft Entra by following prioritized Secure Score recommendations. Enforce MFA, block legacy authentication, and apply risk-based Conditional Access policies to reduce exposure from stale accounts and weak authentication methods. Use built-in tools for user, group, and device administration to detect and clean up identity sprawl—like unused credentials, inactive accounts, and expired apps—before they become vulnerabilities. Jeremy Chapman, Microsoft 365 Director, shares steps to clean up your directory, strengthen authentication, and improve overall identity security. ► QUICK LINKS:  00:00 - Microsoft Entra optimization 00:54 - New Recommendations tab 02:11 - Enforce multifactor authentication 03:21 - Block legacy authentication protocols 03:58 - Apply risk-based Conditional Access 04:44 - Identity sprawl 05:46 - Fix account sprawl 08:06 - Microsoft 365 group sprawl 09:36 - Devices 10:33 - Wrap up ► Link References Watch part one of our Microsoft Entra Beginner's Tutorial series at https://aka.ms/EntraBeginnerMechanics Check out https://aka.ms/MicrosoftEntraRecommendations ► Unfamiliar with Microsoft Mechanics? As Microsoft's official video series for IT, you can watch and share valuable content and demos of current and upcoming tech from the people who build it at Microsoft. • Subscribe to our YouTube: https://www.youtube.com/c/MicrosoftMechanicsSeries • Talk with other IT Pros, join us on the Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog • Watch or listen from anywhere, subscribe to our podcast: https://microsoftmechanics.libsyn.com/podcast ► Keep getting this insider knowledge, join us on social: • Follow us on Twitter: https://twitter.com/MSFTMechanics • Share knowledge on LinkedIn: https://www.linkedin.com/company/microsoft-mechanics/ • Enjoy us on Instagram: https://www.instagram.com/msftmechanics/ • Loosen up with us on TikTok: https://www.tiktok.com/@msftmechanics  

Ctrl+Alt+Azure
293 - The Dawn of Agent IDs in Entra ID

Ctrl+Alt+Azure

Play Episode Listen Later Jun 4, 2025 28:04


The future of generative AI might very well be agentic workloads. Fresh from Build 2025, we take a look at Agent IDs in Entra ID. What are they, and why would even need to know how they work? What's the difference from Enterprise Applications? We consider compliance, reporting, licensing and other aspects on Agent IDs. (00:00) - Intro and catching up.(04:08) - Show content starts.Show links- Agent IDs announcement from Build 2025- Give us feedback!

The Tech Blog Writer Podcast
3291: How Panzura is Modernizing Hybrid Cloud for AI Workloads

The Tech Blog Writer Podcast

Play Episode Listen Later May 27, 2025 31:12


In this episode of Tech Talks Daily, I'm joined by Glen Shok, VP of Product Marketing at Panzura, for a detailed look into how the company is rethinking hybrid cloud storage with the release of CloudFS 8.5 Adapt. CloudFS 8.5 isn't just another update. Built in direct response to customer feedback, it introduces powerful new features like Instant Node and Regional Store that redefine performance, availability, and business continuity. Instant Node allows failed systems to be replaced or migrated in under five minutes.  Regional Store brings high-speed data access closer to end users around the world while reducing latency and cloud egress costs. As Glen explains, the latest release meets the growing demand for flexibility in the face of geopolitical uncertainty, rising cloud costs, and evolving IT infrastructure. Panzura is helping organizations maintain uptime, protect data, and adapt quickly, whether moving away from VMware or modernizing a global IT footprint. CloudFS 8.5 Adapt enables this without forcing customers to compromise on control, performance, or security. We also explore how Panzura's vision for autonomic data infrastructure is becoming a reality. With every CloudFS node sharing full configuration metadata, new nodes can spin up almost instantly. AI plays a central role here too. Through Panzura Data Services, AI tracks behavioral anomalies to detect early signs of data exfiltration, ransomware, or internal threats. This provides not just alerts, but the ability to interdict and isolate risky behavior in real time. Looking ahead, Glen shares how Panzura is preparing to support AI workloads directly where unstructured data lives. Instead of migrating terabytes to external platforms, organizations can train language models in place, reducing cost and complexity. With features like enhanced RBAC, native Entra ID support, and a virtual data lake model on the horizon, Panzura is clearly positioning itself at the intersection of enterprise storage and AI innovation. If you work in cloud infrastructure, cybersecurity, data governance, or AI deployment, this episode offers practical insights into the challenges IT teams face today and the technologies that are solving them.

Microsoft Cloud IT Pro Podcast
Episode 401 – Zero Trust in Microsoft 365

Microsoft Cloud IT Pro Podcast

Play Episode Listen Later May 8, 2025 39:09 Transcription Available


Welcome to Episode 401 of the Microsoft Cloud IT Pro Podcast. In this episode, Ben Stegink and Scott Hoag dive into the intricacies of implementing Zero Trust principles within Microsoft 365 environments. They explore the foundational aspects of Zero Trust, starting with identity management and the importance of Entra ID. They also cover: Identity Management: The critical role of identity in Zero Trust, including MFA, password policies, and least privilege access. Endpoint Security: Strategies for verifying and managing devices, including compliance checks and the balance between corporate and BYOD devices. Networking: The complexities of securing network traffic in a SaaS environment, including conditional access policies and the emerging Global Secure Access feature. Application Management: The role of Defender for Cloud in monitoring shadow IT and ensuring data security across various applications. Data Protection: Techniques for safeguarding sensitive information, including DLP policies and the upcoming network-level DLP capabilities. Join us as we unpack these topics and provide practical insights for enhancing your organization's security posture with Zero Trust.   Your support makes this show possible! Please consider becoming a premium member for access to live shows and more. Check out our membership options. Show Notes Zero Trust deployment for technology pillars Securing identity with Zero Trust Secure endpoints with Zero Trust Secure endpoints with Zero Trust Secure applications with Zero Trust Secure data with Zero Trust Microsoft Zero Trust Assessment About the sponsors Would you like to become the irreplaceable Microsoft 365 resource for your organization? Let us know!

Windows Weekly (MP3)
WW 929: The Blue Screen of Soup - Agent Store, Oblivion Remastered, Ubuntu 25.04

Windows Weekly (MP3)

Play Episode Listen Later Apr 23, 2025 137:50


It's Week D, do you know where your preview update is? 23H2 is out - 24H2, not so much! No surprises in the new features list, but are more new features on the way? Windows New text actions in Click to Do - Practice in Reading Coach and Read with Immersive Reader - in Dev and Beta (24H2) Find cloud-based (OneDrive-based) photos using Semantic search - Comes to EEA, Snapdragon X only for now, Dev and Beta Voice access improvements - add words to custom dictionary - Dev and Beta Updated green screen UI - latest Canary build, from today Minor update to the Beta/23H2 channel, no new features Ubuntu 25.04 is out and there's a native Arm64 ISO (!) and BitLocker support Hands-on with WSL (which is stuck at 24.xx) and in Hyper-V on a Copilot+ PC Is dual-boot even possible on Arm? (Yet) Friday night update to identity caused accounts to be marked as leaked for 50,000 partner accounts AI We're in a new wave: Microsoft 365 Copilot updated, new Agent Store and more on the way Copilot Vision is now free for everyone in Microsoft Edge Google is giving Gemini Advanced/Google One AI Premium away for free to US college students Google estimates its Gemini AI chatbot had 35M DAUs and 350M MAUs worldwide as of last month while ChatGPT had 160M DAUs and 600M MAUs (Erin Woo/The Information) Perplexity is coming to Samsung and Motorola phones - and Microsoft is apparently coming to Motorola too Antitrust It's getting real - 20 years after US v. Microsoft, Big Tech is finally getting a reckoning Google has now lost two major US antitrust cases in less than a year US v. Google (search): DOJ wants Judge to break up Google US v. Google (ads): Google found to have another illegal monopoly What's the "right" outcome for Chrome and Google's ad businesses? OpenAI says it would be happy to buy Chrome from Google- hilarious Google just killed Privacy Sandbox, cites regulatory climate Apple, Meta fined by EU for not conforming to the DMA Apple Intelligence is no longer "available now" (Siri: Is it raining?) Xbox/gaming Elder Scrolls IV Remastered lands on Xbox, PC, PS5 and Game Pass Xbox app arrives on LG smart TVs It's (back) on: Nintendo Switch 2 pre-orders rescheduled to April 24 with no price change And the demand is higher than expected, Nintendo says Tips and Picks Tip of the week: It's time to look at Google Fi again HARDWARE pick of the week: Microsoft keyboards and mice are back, baby RunAs Radio this week: Agentic AI for IT Pros with Tim Warner Brown liquor pick of the week: Dark Harmony No. 3 Black IPA Cask Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsor: spaceship.com/twit

All TWiT.tv Shows (MP3)
Windows Weekly 929: The Blue Screen of Soup

All TWiT.tv Shows (MP3)

Play Episode Listen Later Apr 23, 2025 137:50 Transcription Available


It's Week D, do you know where your preview update is? 23H2 is out - 24H2, not so much! No surprises in the new features list, but are more new features on the way? Windows New text actions in Click to Do - Practice in Reading Coach and Read with Immersive Reader - in Dev and Beta (24H2) Find cloud-based (OneDrive-based) photos using Semantic search - Comes to EEA, Snapdragon X only for now, Dev and Beta Voice access improvements - add words to custom dictionary - Dev and Beta Updated green screen UI - latest Canary build, from today Minor update to the Beta/23H2 channel, no new features Ubuntu 25.04 is out and there's a native Arm64 ISO (!) and BitLocker support Hands-on with WSL (which is stuck at 24.xx) and in Hyper-V on a Copilot+ PC Is dual-boot even possible on Arm? (Yet) Friday night update to identity caused accounts to be marked as leaked for 50,000 partner accounts AI We're in a new wave: Microsoft 365 Copilot updated, new Agent Store and more on the way Copilot Vision is now free for everyone in Microsoft Edge Google is giving Gemini Advanced/Google One AI Premium away for free to US college students Google estimates its Gemini AI chatbot had 35M DAUs and 350M MAUs worldwide as of last month while ChatGPT had 160M DAUs and 600M MAUs (Erin Woo/The Information) Perplexity is coming to Samsung and Motorola phones - and Microsoft is apparently coming to Motorola too Antitrust It's getting real - 20 years after US v. Microsoft, Big Tech is finally getting a reckoning Google has now lost two major US antitrust cases in less than a year US v. Google (search): DOJ wants Judge to break up Google US v. Google (ads): Google found to have another illegal monopoly What's the "right" outcome for Chrome and Google's ad businesses? OpenAI says it would be happy to buy Chrome from Google- hilarious Google just killed Privacy Sandbox, cites regulatory climate Apple, Meta fined by EU for not conforming to the DMA Apple Intelligence is no longer "available now" (Siri: Is it raining?) Xbox/gaming Elder Scrolls IV Remastered lands on Xbox, PC, PS5 and Game Pass Xbox app arrives on LG smart TVs It's (back) on: Nintendo Switch 2 pre-orders rescheduled to April 24 with no price change And the demand is higher than expected, Nintendo says Tips and Picks Tip of the week: It's time to look at Google Fi again HARDWARE pick of the week: Microsoft keyboards and mice are back, baby RunAs Radio this week: Agentic AI for IT Pros with Tim Warner Brown liquor pick of the week: Dark Harmony No. 3 Black IPA Cask Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsor: spaceship.com/twit

Radio Leo (Audio)
Windows Weekly 929: The Blue Screen of Soup

Radio Leo (Audio)

Play Episode Listen Later Apr 23, 2025 137:50 Transcription Available


It's Week D, do you know where your preview update is? 23H2 is out - 24H2, not so much! No surprises in the new features list, but are more new features on the way? Windows New text actions in Click to Do - Practice in Reading Coach and Read with Immersive Reader - in Dev and Beta (24H2) Find cloud-based (OneDrive-based) photos using Semantic search - Comes to EEA, Snapdragon X only for now, Dev and Beta Voice access improvements - add words to custom dictionary - Dev and Beta Updated green screen UI - latest Canary build, from today Minor update to the Beta/23H2 channel, no new features Ubuntu 25.04 is out and there's a native Arm64 ISO (!) and BitLocker support Hands-on with WSL (which is stuck at 24.xx) and in Hyper-V on a Copilot+ PC Is dual-boot even possible on Arm? (Yet) Friday night update to identity caused accounts to be marked as leaked for 50,000 partner accounts AI We're in a new wave: Microsoft 365 Copilot updated, new Agent Store and more on the way Copilot Vision is now free for everyone in Microsoft Edge Google is giving Gemini Advanced/Google One AI Premium away for free to US college students Google estimates its Gemini AI chatbot had 35M DAUs and 350M MAUs worldwide as of last month while ChatGPT had 160M DAUs and 600M MAUs (Erin Woo/The Information) Perplexity is coming to Samsung and Motorola phones - and Microsoft is apparently coming to Motorola too Antitrust It's getting real - 20 years after US v. Microsoft, Big Tech is finally getting a reckoning Google has now lost two major US antitrust cases in less than a year US v. Google (search): DOJ wants Judge to break up Google US v. Google (ads): Google found to have another illegal monopoly What's the "right" outcome for Chrome and Google's ad businesses? OpenAI says it would be happy to buy Chrome from Google- hilarious Google just killed Privacy Sandbox, cites regulatory climate Apple, Meta fined by EU for not conforming to the DMA Apple Intelligence is no longer "available now" (Siri: Is it raining?) Xbox/gaming Elder Scrolls IV Remastered lands on Xbox, PC, PS5 and Game Pass Xbox app arrives on LG smart TVs It's (back) on: Nintendo Switch 2 pre-orders rescheduled to April 24 with no price change And the demand is higher than expected, Nintendo says Tips and Picks Tip of the week: It's time to look at Google Fi again HARDWARE pick of the week: Microsoft keyboards and mice are back, baby RunAs Radio this week: Agentic AI for IT Pros with Tim Warner Brown liquor pick of the week: Dark Harmony No. 3 Black IPA Cask Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsor: spaceship.com/twit

Windows Weekly (Video HI)
WW 929: The Blue Screen of Soup - Agent Store, Oblivion Remastered, Ubuntu 25.04

Windows Weekly (Video HI)

Play Episode Listen Later Apr 23, 2025 137:50


It's Week D, do you know where your preview update is? 23H2 is out - 24H2, not so much! No surprises in the new features list, but are more new features on the way? Windows New text actions in Click to Do - Practice in Reading Coach and Read with Immersive Reader - in Dev and Beta (24H2) Find cloud-based (OneDrive-based) photos using Semantic search - Comes to EEA, Snapdragon X only for now, Dev and Beta Voice access improvements - add words to custom dictionary - Dev and Beta Updated green screen UI - latest Canary build, from today Minor update to the Beta/23H2 channel, no new features Ubuntu 25.04 is out and there's a native Arm64 ISO (!) and BitLocker support Hands-on with WSL (which is stuck at 24.xx) and in Hyper-V on a Copilot+ PC Is dual-boot even possible on Arm? (Yet) Friday night update to identity caused accounts to be marked as leaked for 50,000 partner accounts AI We're in a new wave: Microsoft 365 Copilot updated, new Agent Store and more on the way Copilot Vision is now free for everyone in Microsoft Edge Google is giving Gemini Advanced/Google One AI Premium away for free to US college students Google estimates its Gemini AI chatbot had 35M DAUs and 350M MAUs worldwide as of last month while ChatGPT had 160M DAUs and 600M MAUs (Erin Woo/The Information) Perplexity is coming to Samsung and Motorola phones - and Microsoft is apparently coming to Motorola too Antitrust It's getting real - 20 years after US v. Microsoft, Big Tech is finally getting a reckoning Google has now lost two major US antitrust cases in less than a year US v. Google (search): DOJ wants Judge to break up Google US v. Google (ads): Google found to have another illegal monopoly What's the "right" outcome for Chrome and Google's ad businesses? OpenAI says it would be happy to buy Chrome from Google- hilarious Google just killed Privacy Sandbox, cites regulatory climate Apple, Meta fined by EU for not conforming to the DMA Apple Intelligence is no longer "available now" (Siri: Is it raining?) Xbox/gaming Elder Scrolls IV Remastered lands on Xbox, PC, PS5 and Game Pass Xbox app arrives on LG smart TVs It's (back) on: Nintendo Switch 2 pre-orders rescheduled to April 24 with no price change And the demand is higher than expected, Nintendo says Tips and Picks Tip of the week: It's time to look at Google Fi again HARDWARE pick of the week: Microsoft keyboards and mice are back, baby RunAs Radio this week: Agentic AI for IT Pros with Tim Warner Brown liquor pick of the week: Dark Harmony No. 3 Black IPA Cask Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsor: spaceship.com/twit

5bytespodcast
Entra ID Account Lockouts! Critical PyTorch Bug! Scheduled Tasks for Gemini!

5bytespodcast

Play Episode Listen Later Apr 23, 2025 18:50


I cover the news over the weekend about Entra ID account lockouts, I discuss several recent vulnerabilities, a policy change by Google and more! Reference Links: https://www.rorymon.com/blog/entra-id-account-lockouts-critical-pytorch-bug-scheduled-tasks-for-gemini/

All TWiT.tv Shows (Video LO)
Windows Weekly 929: The Blue Screen of Soup

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Apr 23, 2025 137:50 Transcription Available


It's Week D, do you know where your preview update is? 23H2 is out - 24H2, not so much! No surprises in the new features list, but are more new features on the way? Windows New text actions in Click to Do - Practice in Reading Coach and Read with Immersive Reader - in Dev and Beta (24H2) Find cloud-based (OneDrive-based) photos using Semantic search - Comes to EEA, Snapdragon X only for now, Dev and Beta Voice access improvements - add words to custom dictionary - Dev and Beta Updated green screen UI - latest Canary build, from today Minor update to the Beta/23H2 channel, no new features Ubuntu 25.04 is out and there's a native Arm64 ISO (!) and BitLocker support Hands-on with WSL (which is stuck at 24.xx) and in Hyper-V on a Copilot+ PC Is dual-boot even possible on Arm? (Yet) Friday night update to identity caused accounts to be marked as leaked for 50,000 partner accounts AI We're in a new wave: Microsoft 365 Copilot updated, new Agent Store and more on the way Copilot Vision is now free for everyone in Microsoft Edge Google is giving Gemini Advanced/Google One AI Premium away for free to US college students Google estimates its Gemini AI chatbot had 35M DAUs and 350M MAUs worldwide as of last month while ChatGPT had 160M DAUs and 600M MAUs (Erin Woo/The Information) Perplexity is coming to Samsung and Motorola phones - and Microsoft is apparently coming to Motorola too Antitrust It's getting real - 20 years after US v. Microsoft, Big Tech is finally getting a reckoning Google has now lost two major US antitrust cases in less than a year US v. Google (search): DOJ wants Judge to break up Google US v. Google (ads): Google found to have another illegal monopoly What's the "right" outcome for Chrome and Google's ad businesses? OpenAI says it would be happy to buy Chrome from Google- hilarious Google just killed Privacy Sandbox, cites regulatory climate Apple, Meta fined by EU for not conforming to the DMA Apple Intelligence is no longer "available now" (Siri: Is it raining?) Xbox/gaming Elder Scrolls IV Remastered lands on Xbox, PC, PS5 and Game Pass Xbox app arrives on LG smart TVs It's (back) on: Nintendo Switch 2 pre-orders rescheduled to April 24 with no price change And the demand is higher than expected, Nintendo says Tips and Picks Tip of the week: It's time to look at Google Fi again HARDWARE pick of the week: Microsoft keyboards and mice are back, baby RunAs Radio this week: Agentic AI for IT Pros with Tim Warner Brown liquor pick of the week: Dark Harmony No. 3 Black IPA Cask Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsor: spaceship.com/twit

Cloud Security Podcast
Cloud Incident Response in Microsoft Azure

Cloud Security Podcast

Play Episode Listen Later Feb 20, 2025 54:15


In this episode, we dive deep into Azure security, incident response, and the evolving cloud threat landscape with Katie Knowles, Security Researcher and former Azure Incident Responder. We spoke about common Azure incident response scenarios you need to prepare for, how identity and privilege escalation work in Azure, how Active Directory and Entra ID expose new risks and what security teams need to know about Azure networking and logging.Guest Socials: ⁠⁠⁠⁠⁠⁠⁠⁠⁠Katie's LinkedinPodcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:-⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠- ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp⁠⁠⁠⁠⁠⁠⁠If you are interested in AI Cybersecurity, you can check out our sister podcast -⁠⁠⁠⁠⁠⁠⁠ AI Cybersecurity PodcastQuestions asked:(00:00) Introduction(02:27) A bit about Katie(03:17) Domain Admin in Azure(07:03) Common causes of incidents in Azure(08:53) Identities in Azure(11:44) Third Party Identities in Azure(17:34) Azure Networking and Incident Response(22:35) Common Incidents in Azure(26:53) AI specific incidents in Azure(28:45) Privilege escalation in Azure(39:37) Where to start with Azure Research?(48:20) The Fun Questions

Windows Weekly (MP3)
WW 920: Celebrity Condiments - Quantum Processing Unit, Edge 132, Rust

Windows Weekly (MP3)

Play Episode Listen Later Feb 19, 2025 161:41


On this episode, Paul Thurrott, Leo Laporte, and Richard Campbell explore the Windows KB5052086 update, the new Linux kernel drama, quantum computing, and more. Microsoft has announced the very first QPU, powered by topological qubits! Can the hosts possibly comprehend how this works? Later, Paul strongly emphasizes how AI can save users lots of time. Finally, Richard features a whisky that was recently brought to his 30th wedding anniversary! Windows Dev channel: "Important" update because of the coming change to Recall soon, so here's an update that will wipe out all your data. One guess about what that means. Plus, a nice change to the Recall pop-up Release Preview (24H2): A preview of the preview that we'll preview next time Release Preview (23H2): Basically the same features as above, keeping the two aligned Microsoft deprecates location history in Windows 11 - depreciation junction, what's your function? Microsoft Edge gets more WebUI 2-based performance improvements Clipchamp just keeps getting better Microsoft 365 Microsoft: Just kidding about that MSA and Entra ID sign-in experience change Outlook mobile is getting a new font picker, a recall email feature (finally), and a minimize email message feature. ExpressVPN (TWiT sponsor) rewrote its VPN protocol in Rust AI Microsoft announces a Quantum computing breakthrough, first quantum processor Flareup in Linux kernel management maps directly to what we see with AI - Two extremes but a clear middle ground Long story short, AI is all about saving you time - this is the "many small things, not one big thing" argument Copilot gets new voice capabilities In case you were worried, OpenAI formally rejects buyout offer OpenAI will also simplify its model offerings Google Gemini now remembers what you said, unlike your husband xAI launches Grok3 model but only for X Premium subscribers Xbox Avowed launches, with many other Game Pass titles coming through the end of February Microsoft announced a generative AI model for video games Sony just had its best-ever PS5 sales quarter Tips and Picks Tip of the week: Find your AI "ah-ha" moment App pick of the week: Notion. And iA Writer 2 for Windows is here RunAs Radio this week: Managed DevOps Pools with Eliza Tarasila Brown liquor pick of the week: Signal Hill Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: uscloud.com zscaler.com/security 1password.com/windowsweekly

All TWiT.tv Shows (MP3)
Windows Weekly 920: Celebrity Condiments

All TWiT.tv Shows (MP3)

Play Episode Listen Later Feb 19, 2025 161:41


On this episode, Paul Thurrott, Leo Laporte, and Richard Campbell explore the Windows KB5052086 update, the new Linux kernel drama, quantum computing, and more. Microsoft has announced the very first QPU, powered by topological qubits! Can the hosts possibly comprehend how this works? Later, Paul strongly emphasizes how AI can save users lots of time. Finally, Richard features a whisky that was recently brought to his 30th wedding anniversary! Windows Dev channel: "Important" update because of the coming change to Recall soon, so here's an update that will wipe out all your data. One guess about what that means. Plus, a nice change to the Recall pop-up Release Preview (24H2): A preview of the preview that we'll preview next time Release Preview (23H2): Basically the same features as above, keeping the two aligned Microsoft deprecates location history in Windows 11 - depreciation junction, what's your function? Microsoft Edge gets more WebUI 2-based performance improvements Clipchamp just keeps getting better Microsoft 365 Microsoft: Just kidding about that MSA and Entra ID sign-in experience change Outlook mobile is getting a new font picker, a recall email feature (finally), and a minimize email message feature. ExpressVPN (TWiT sponsor) rewrote its VPN protocol in Rust AI Microsoft announces a Quantum computing breakthrough, first quantum processor Flareup in Linux kernel management maps directly to what we see with AI - Two extremes but a clear middle ground Long story short, AI is all about saving you time - this is the "many small things, not one big thing" argument Copilot gets new voice capabilities In case you were worried, OpenAI formally rejects buyout offer OpenAI will also simplify its model offerings Google Gemini now remembers what you said, unlike your husband xAI launches Grok3 model but only for X Premium subscribers Xbox Avowed launches, with many other Game Pass titles coming through the end of February Microsoft announced a generative AI model for video games Sony just had its best-ever PS5 sales quarter Tips and Picks Tip of the week: Find your AI "ah-ha" moment App pick of the week: Notion. And iA Writer 2 for Windows is here RunAs Radio this week: Managed DevOps Pools with Eliza Tarasila Brown liquor pick of the week: Signal Hill Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: uscloud.com zscaler.com/security 1password.com/windowsweekly

Radio Leo (Audio)
Windows Weekly 920: Celebrity Condiments

Radio Leo (Audio)

Play Episode Listen Later Feb 19, 2025 161:41


On this episode, Paul Thurrott, Leo Laporte, and Richard Campbell explore the Windows KB5052086 update, the new Linux kernel drama, quantum computing, and more. Microsoft has announced the very first QPU, powered by topological qubits! Can the hosts possibly comprehend how this works? Later, Paul strongly emphasizes how AI can save users lots of time. Finally, Richard features a whisky that was recently brought to his 30th wedding anniversary! Windows Dev channel: "Important" update because of the coming change to Recall soon, so here's an update that will wipe out all your data. One guess about what that means. Plus, a nice change to the Recall pop-up Release Preview (24H2): A preview of the preview that we'll preview next time Release Preview (23H2): Basically the same features as above, keeping the two aligned Microsoft deprecates location history in Windows 11 - depreciation junction, what's your function? Microsoft Edge gets more WebUI 2-based performance improvements Clipchamp just keeps getting better Microsoft 365 Microsoft: Just kidding about that MSA and Entra ID sign-in experience change Outlook mobile is getting a new font picker, a recall email feature (finally), and a minimize email message feature. ExpressVPN (TWiT sponsor) rewrote its VPN protocol in Rust AI Microsoft announces a Quantum computing breakthrough, first quantum processor Flareup in Linux kernel management maps directly to what we see with AI - Two extremes but a clear middle ground Long story short, AI is all about saving you time - this is the "many small things, not one big thing" argument Copilot gets new voice capabilities In case you were worried, OpenAI formally rejects buyout offer OpenAI will also simplify its model offerings Google Gemini now remembers what you said, unlike your husband xAI launches Grok3 model but only for X Premium subscribers Xbox Avowed launches, with many other Game Pass titles coming through the end of February Microsoft announced a generative AI model for video games Sony just had its best-ever PS5 sales quarter Tips and Picks Tip of the week: Find your AI "ah-ha" moment App pick of the week: Notion. And iA Writer 2 for Windows is here RunAs Radio this week: Managed DevOps Pools with Eliza Tarasila Brown liquor pick of the week: Signal Hill Hosts: Leo Laporte, Paul Thurrott, and Richard Campbell Download or subscribe to Windows Weekly at https://twit.tv/shows/windows-weekly Check out Paul's blog at thurrott.com The Windows Weekly theme music is courtesy of Carl Franklin. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free shows, a members-only Discord, and behind-the-scenes access. Join today: https://twit.tv/clubtwit Sponsors: uscloud.com zscaler.com/security 1password.com/windowsweekly